{
  "slug": "patch-sla-backlog",
  "title": "Patch SLA Backlog Calculator",
  "heading": "Patch Management SLA Backlog Calculator",
  "category": "other",
  "url": "https://www.revenuelab.fyi/toolbox/patch-sla-backlog",
  "summary": "See if your patching throughput can clear the vulnerability backlog before it grows.",
  "description": "Most vulnerability management programs fail not from lack of tooling but from a simple throughput math problem: new critical and high vulnerabilities arrive faster than the team can remediate them within SLA. This calculator compares your new-vulnerability arrival rate against your remediation rate to determine whether your backlog is shrinking, holding steady, or growing, and projects how many vulnerabilities will still be open and out of SLA in 90 days at current pace. SLA windows commonly used across the industry are 15 days for critical, 30 for high, 90 for medium, per CISA Binding Operational Directive timelines and common enterprise policy, though your own SLA may differ. The output also estimates the additional remediation capacity (patches per week) needed to hit a zero-backlog target, which is the number security leaders actually need when asking for more patching headcount or automation tooling budget.",
  "formula": "Net weekly change = new vulnerabilities/week − remediated/week. Backlog in N weeks = current backlog + (net weekly change × N). Required rate to clear SLA = (current backlog + inflow over SLA window) ÷ SLA window in weeks.",
  "dateModified": "2026-09-30",
  "run_url": "https://www.revenuelab.fyi/api/public/calc?tool=patch-sla-backlog",
  "inputs": [
    {
      "id": "currentBacklog",
      "label": "Current open critical/high vulnerabilities",
      "kind": "number",
      "hint": null,
      "default": 240,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "newPerWeek",
      "label": "New critical/high vulnerabilities per week",
      "kind": "number",
      "hint": null,
      "default": 35,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "remediatedPerWeek",
      "label": "Vulnerabilities remediated per week",
      "kind": "number",
      "hint": null,
      "default": 28,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "slaDays",
      "label": "SLA window (critical/high)",
      "kind": "number",
      "hint": null,
      "default": 15,
      "unit": null,
      "min": 1,
      "max": 180
    },
    {
      "id": "projectionWeeks",
      "label": "Project forward",
      "kind": "number",
      "hint": null,
      "default": 12,
      "unit": null,
      "min": 1,
      "max": 104
    }
  ],
  "outputs": [
    {
      "id": "projectedBacklog",
      "label": "Projected backlog",
      "format": "number",
      "hint": null,
      "primary": true
    },
    {
      "id": "netWeekly",
      "label": "Net weekly change (+growing / -shrinking)",
      "format": "number",
      "hint": null,
      "primary": false
    },
    {
      "id": "requiredRate",
      "label": "Remediation rate needed to hit SLA",
      "format": "decimal",
      "hint": null,
      "primary": false
    },
    {
      "id": "rateGap",
      "label": "Additional remediations/week needed",
      "format": "decimal",
      "hint": null,
      "primary": false
    },
    {
      "id": "slaWeeks",
      "label": "SLA window in weeks",
      "format": "decimal",
      "hint": null,
      "primary": false
    }
  ],
  "worked_example": {
    "inputs": [
      "Current open critical/high vulnerabilities: 240",
      "New critical/high vulnerabilities per week: 35",
      "Vulnerabilities remediated per week: 28",
      "SLA window (critical/high): 15",
      "Project forward: 12"
    ],
    "outputs": [
      "Projected backlog: 324",
      "Net weekly change (+growing / -shrinking): 7",
      "Remediation rate needed to hit SLA: 147",
      "Additional remediations/week needed: 119",
      "SLA window in weeks: 2.1"
    ]
  },
  "how_to": {
    "title": "How to use this",
    "steps": [
      "Enter current open critical/high vulnerabilities.",
      "Enter new critical/high vulnerabilities per week.",
      "Enter vulnerabilities remediated per week.",
      "Enter sla window (critical/high).",
      "Enter project forward.",
      "Read your projected backlog on the right — it updates as you type.",
      "Hit Share to keep the scenario or send it to someone."
    ]
  },
  "scenarios": [
    {
      "name": "Conservative",
      "description": "Lower-end numbers — what if things land soft?",
      "values": {
        "currentBacklog": 140,
        "newPerWeek": 21,
        "remediatedPerWeek": 17,
        "slaDays": 9,
        "projectionWeeks": 7
      }
    },
    {
      "name": "Typical",
      "description": "Defaults — the most common real-world setup.",
      "values": {
        "currentBacklog": 240,
        "newPerWeek": 35,
        "remediatedPerWeek": 28,
        "slaDays": 15,
        "projectionWeeks": 12
      }
    },
    {
      "name": "Ambitious",
      "description": "Higher-end numbers — what if things really pop?",
      "values": {
        "currentBacklog": 380,
        "newPerWeek": 56,
        "remediatedPerWeek": 45,
        "slaDays": 24,
        "projectionWeeks": 19
      }
    }
  ],
  "limitations": [
    "Estimates assume standard, average conditions — local rules, pricing, and materials vary.",
    "Results are rounded for readability; add a buffer before ordering, booking, or committing.",
    "Double-check anything with a real cost attached against a local quote."
  ],
  "faq": [
    {
      "q": "What SLA windows are actually standard?",
      "a": "CISA's Binding Operational Directive 22-01 requires federal agencies to remediate known exploited vulnerabilities within a set window, and most enterprise vulnerability management policies mirror or tighten that with roughly 15 days for critical, 30 for high, 60-90 for medium, and 90-180 for low severity, though regulated industries like finance and healthcare often run tighter timelines."
    },
    {
      "q": "My backlog is growing even though we're patching every week, what's going on?",
      "a": "This is the most common vulnerability management failure mode: your remediation rate is a fixed capacity (people, change windows, testing cycles) while new vulnerability disclosure volume keeps climbing industry-wide. The fix is either increasing remediation throughput through automation and pre-approved patch windows, or reducing attack surface so fewer systems generate new findings in the first place."
    },
    {
      "q": "Should every vulnerability actually get patched?",
      "a": "No, mature programs risk-score and often accept or compensate for vulnerabilities that aren't internet-facing, don't have known exploits, or sit behind other controls, rather than treating every scanner finding as equal. Applying that filtering before counting your backlog gives a far more realistic and achievable throughput target than trying to patch everything."
    },
    {
      "q": "How much does automation actually move the remediation rate?",
      "a": "Organizations moving from manual patch testing and deployment to automated patch management with staged rollout groups commonly see remediation throughput increase 40-70%, mainly by cutting the manual scheduling and verification overhead that dominates patch cycle time more than the actual patching work itself."
    }
  ],
  "related": [
    "https://www.revenuelab.fyi/toolbox/soc-staffing-coverage",
    "https://www.revenuelab.fyi/toolbox/mttd-mttr-cost-impact",
    "https://www.revenuelab.fyi/toolbox/pen-test-vs-bug-bounty"
  ],
  "license": "CC-BY-4.0",
  "citation": "RevenueLab — Patch SLA Backlog Calculator (https://www.revenuelab.fyi/toolbox/patch-sla-backlog)"
}